StackRadar

CVE-2026-39315

Medium

Advisory

Published 9 Apr 2026In the index since 8 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
unheadnpm1.8.10, 1.9.9, 1.9.13, 2.0.19+1 more2.1.1310
OSV records
GHSA-95h2-gj7x-gx9w

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-39315.

Container imageDigestPackageFixed in
litlyx/litlyx-dashboard:lateste64ff2d52385
unhead@2.0.19
2.1.13

Open the chart page →

7,874
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-39315.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
unhead@1.8.10
2.1.13

Open the chart page →

32,501
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-39315.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
unhead@1.9.9
2.1.13

Open the chart page →

4,551
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-39315.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
unhead@2.1.12
2.1.13

Open the chart page →

3,798
s3-browsers3-browser0.4.11 of 1See more

s3-browser s3-browser 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-39315.

Container imageDigestPackageFixed in
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
unhead@2.1.12
2.1.13

Open the chart page →

576
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2026-39315.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.19.2-branch.hotfix-2.19.1.124125-665e7e14f9241665ae3
unhead@1.9.13
2.1.13

Open the chart page →

16,368
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2026-39315.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbfdc008effc7a
unhead@1.9.13
2.1.13

Open the chart page →

16,400
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2026-39315.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.6-branch.testing1.154030-9b0911432fc940d9b4c
unhead@1.9.13
2.1.13

Open the chart page →

16,400
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-39315.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.2-branch.testing4.134160-9fad4b210ad4ade8bf2
unhead@1.9.13
2.1.13

Open the chart page →

16,019
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-39315.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
unhead@1.9.13
2.1.13

Open the chart page →

15,635

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
directus/directus:11.1.0e3c8bb975350
unhead@1.9.9
2.1.13
1
litlyx/litlyx-dashboard:lateste64ff2d52385
unhead@2.0.19
2.1.13
1
speckle/speckle-frontend-2:2.20.2-branch.testing4.134160-9fad4b210ad4ade8bf2
unhead@1.9.13
2.1.13
1
speckle/speckle-frontend-2:2.20.6-branch.testing1.154030-9b0911432fc940d9b4c
unhead@1.9.13
2.1.13
1
speckle/speckle-frontend-2:2.19.2-branch.hotfix-2.19.1.124125-665e7e14f9241665ae3
unhead@1.9.13
2.1.13
1
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
unhead@1.9.13
2.1.13
1
speckle/speckle-frontend-2:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbfdc008effc7a
unhead@1.9.13
2.1.13
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
unhead@2.1.12
2.1.13
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
unhead@1.8.10
2.1.13
1
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
unhead@2.1.12
2.1.13
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.